DNS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationDNS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old August 22nd, 2011, 12:00 PM
couttsj couttsj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2011
Posts: 165 couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 2 Days 16 h 29 m 48 sec
Reputation Power: 43
Yahoo DNS Abuse

Am I the only one having a problem with Yahoo DNS servers bombarding our server with type 99 (SPF) requests. The maximum number of requests received one day last week was 55,987, but it looks like today may set a new record.

J.A. Coutts

Reply With Quote
  #2  
Old August 22nd, 2011, 12:22 PM
CaptPikel CaptPikel is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2010
Location: Florida
Posts: 248 CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level)CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level)CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 3 Days 15 h 26 m 11 sec
Reputation Power: 3
Could be people spoofing sending mail from your domain and yahoo's servers just doing the proper procedure for spf enforcing. You can try setting the TTL for the TXT/SPF statement higher. It may cut back on the queries (unless they do a lookup per email coming in). Probably better to have SPF queries coming in than spammers getting your domain blacklisted.

Or it could be someone just using their servers will ill intent. Are the servers querying you open to recursion?

Reply With Quote
  #3  
Old August 22nd, 2011, 08:04 PM
couttsj couttsj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2011
Posts: 165 couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 2 Days 16 h 29 m 48 sec
Reputation Power: 43
Quote:
Originally Posted by CaptPikel
Could be people spoofing sending mail from your domain and yahoo's servers just doing the proper procedure for spf enforcing. You can try setting the TTL for the TXT/SPF statement higher. It may cut back on the queries (unless they do a lookup per email coming in). Probably better to have SPF queries coming in than spammers getting your domain blacklisted.

Or it could be someone just using their servers will ill intent. Are the servers querying you open to recursion?

Servers used are:
67.195.128.48-51
68.142.209.135-138
68.142.209.143-146
68.142.209.151-158
72.30.192.150-155
72.30.192.164-171
74.6.109.17-20
74.6.109.24-27
98.139.193.152-159
I assume these are internal servers, as they do not respond to port 53. Part of the problem is that Yahoo does not check for TXT records, and our DNS does not support type 99 requests. It just rotates through the round robin servers asking the same question several times. I have blocked most of the servers, but it hasn't slowed the onslaught. Yahoo just ignores all my abuse complaints.

J.A. Coutts

Reply With Quote
  #4  
Old August 25th, 2011, 10:33 AM
couttsj couttsj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2011
Posts: 165 couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 2 Days 16 h 29 m 48 sec
Reputation Power: 43
New record established yesterday.

67.195.128.48-51 8,395
68.142.209.135-138 2,522
68.142.209.143-146 28,083
68.142.209.151-158 5,895
72.30.192.150-155 0
72.30.192.164-171 11,278
74.6.109.17-20 3,960
74.6.109.24-27 4,225
98.139.193.152-159 14,248
------------------ -------
Total 78,606

Still no response from Yahoo, even though I have a problem number.

J.A. Coutts

Reply With Quote
  #5  
Old August 25th, 2011, 11:04 AM
CaptPikel CaptPikel is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2010
Location: Florida
Posts: 248 CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level)CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level)CaptPikel User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 3 Days 15 h 26 m 11 sec
Reputation Power: 3
Yeah that seems pretty sketchy. I guess there isn't much you can do except wait or block IP's. I only have a very small test domain I can check queries on and I don't get that. So not sure on this one.

Reply With Quote
  #6  
Old September 9th, 2011, 02:41 PM
couttsj couttsj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2011
Posts: 165 couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 2 Days 16 h 29 m 48 sec
Reputation Power: 43
Yahoo DNS Abuse continues

Yesterday, our DNS server received 88,715 requests (97% of all requests) from Yahoo, and I have had absolutely zero non-automated response from Yahoo. The volume is so high that it is starting to flood the NAT table in our router.

Yahoo appears to be using SPF to delay incoming mail delivery. Our Pseudo SMTP server (which rejects all incoming messages with a 550 error), recorded 88 attempts from various Yahoo mail servers to send a message to very obviously random generated email addresses in our domain. The DNS queries seem highly disproportionate to the rejection messages sent

Does anyone know if Yahoo uses a Domain Name Block List such as the Spamhaus DBL? I am getting desperate.

J.A. Coutts

Reply With Quote
  #7  
Old November 9th, 2011, 10:49 AM
couttsj couttsj is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2011
Posts: 165 couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level)couttsj User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 2 Days 16 h 29 m 48 sec
Reputation Power: 43
Yayoo DNS abuse suddenly stopped

I have no idea why, but for the last 7 days the bombardment has ceased. Not only that, but there have been zero requests for type 99 or TXT records from anywhere.

Anyone have any idea what is going on? Has Yahoo abandoned their SPF attempts?

J.A. Coutts

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationDNS > Yahoo DNS Abuse

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap